Pan American Group Discloses Data Breach Affecting Employees in Kansas and Missouri
Pan American Group LLC, a subsidiary of Flynn Restaurant Group and operator of Panera Bread locations in Kansas and Missouri, reported a data breach that occurred in April 2026. The incident was disclosed to the California Attorney General on August 24, 2026, and to the Massachusetts Office of Consumer Affairs and Business Regulation on August 26, with notifications sent to affected individuals beginning the same day.
On April 9, 2026, the company detected unauthorized activity on its network, prompting an investigation. The breach, which took place between April 8 and April 9, involved an unknown actor accessing files containing sensitive personal information. Exposed data included Social Security numbers, medical records, financial account details, driver’s license numbers, and credit or debit card information.
The breach primarily impacted current and former employees rather than customers. In response, Pan American Group is offering complimentary credit monitoring and identity theft protection services through CyberScout, a TransUnion company, with enrollment available for 90 days via a unique code provided in notification letters. Affected individuals may also contact the company’s dedicated assistance line or submit inquiries in writing to its legal department in Independence, Ohio.
Source: https://www.claimdepot.com/data-breach/pan-american-group-2026
Flynn Group cybersecurity rating report: https://www.rankiteo.com/company/flynn-restaurants-group
"id": "FLY1787863700",
"linkid": "flynn-restaurants-group",
"type": "Breach",
"date": "4/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': '0',
'industry': 'Restaurant',
'location': 'Kansas and Missouri, USA',
'name': 'Pan American Group LLC',
'type': 'Subsidiary'}],
'customer_advisories': 'Notifications sent to affected individuals with '
'details on credit monitoring and identity theft '
'protection services',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Social Security numbers',
'medical records',
'financial account details',
'driver’s license numbers',
'credit or debit card '
'information']},
'date_detected': '2026-04-09',
'date_publicly_disclosed': '2026-08-24',
'description': 'Pan American Group LLC, a subsidiary of Flynn Restaurant '
'Group and operator of Panera Bread locations in Kansas and '
'Missouri, reported a data breach that occurred in April 2026. '
'The incident involved unauthorized access to files containing '
'sensitive personal information of current and former '
'employees.',
'impact': {'data_compromised': 'Social Security numbers, medical records, '
'financial account details, driver’s license '
'numbers, and credit or debit card information',
'identity_theft_risk': 'High',
'payment_information_risk': 'High'},
'investigation_status': 'Ongoing',
'references': [{'date_accessed': '2026-08-24',
'source': 'California Attorney General'},
{'date_accessed': '2026-08-26',
'source': 'Massachusetts Office of Consumer Affairs and '
'Business Regulation'}],
'regulatory_compliance': {'regulatory_notifications': ['California Attorney '
'General',
'Massachusetts Office '
'of Consumer Affairs '
'and Business '
'Regulation']},
'response': {'communication_strategy': 'Notifications sent to affected '
'individuals via mail; dedicated '
'assistance line and written inquiries '
'to legal department',
'third_party_assistance': 'CyberScout (TransUnion)'},
'title': 'Pan American Group Data Breach Affecting Employees in Kansas and '
'Missouri',
'type': 'Data Breach'}